Daily pulse
Each day Watch checks TLS and certificate days remaining, security headers, mixed content, HTTP to HTTPS, and common exposed paths. This is a lightweight origin check, not a ZAP-backed Standard scan.
Daily pulse for headers, certificate expiry, and exposed paths. Pick Standard or Deep for the weekly scan when you add the site. Email when something new appears. From $29 per site per month.
Daily pulse on every seat. Weekly Standard or Deep, locked at checkout. Credits are not charged for included runs.
Each day Watch checks TLS and certificate days remaining, security headers, mixed content, HTTP to HTTPS, and common exposed paths. This is a lightweight origin check, not a ZAP-backed Standard scan.
When you add a site, pick Standard (~5-7 minutes, ~80 checks) or Deep (~12-15 minutes, ~120 checks) for the weekly scan. That depth is locked for the seat. Open the run from scan history when you need the full finding list. Comprehensive stays on credits.
After the first baseline, you get email when something new or worse appears, when the score drops past your threshold, or when the certificate hits 30, 14, 7, or expired. Mute noisy findings. Unmute them from the same watch page.
Standard is $29 per site per month ($290/year). Deep is $49 ($490/year). Pause keeps the paid seat. Cancel drops it at period end. Unused seats only attach to a new origin of the same depth. Included pulse and weekly runs do not use credits.
See pricing · Scheduled Scans stay on credits for custom cadence.
A dashboard scan is a snapshot. Watch is the daily pulse and weekly Standard or Deep that follows.
After you finish a scan, add the same HTTPS origin to Watch when you want change alerts instead of another one-off credit run. Daily pulse plus weekly Standard or Deep. Included runs do not use credits. Standard is $29 per site per month. Deep is $49.
Still deciding between a scan, Watch, and a pentest? Website Security Scanner · $297 Penetration Test · $497 Comprehensive Pentest.
Add one HTTPS origin per seat. Pick Standard or Deep. Checkout opens when you need another seat of that depth.
Sign in and go to /watch. The Watch item sits next to Scheduled. The dashboard card shows how many sites you are watching versus paid seats.
Enter a name such as Shop production, the HTTPS URL, monthly or yearly billing, and Standard or Deep. Click Watch website. Unused paid seats attach only when they match that depth. Otherwise Stripe Checkout opens for a new seat.
The first pulse and first weekly Standard or Deep scan record what already exists. You should not expect an inbox full of historical findings on day one. Open the watch to see last pulse, last weekly scan, and certificate days.
Set new findings, resolved findings, score drop, minimum severity, quiet hours, timezone, extra recipients, and weekly digest. Mute accepted risk. Click Unmute on that row or under Muted issues when you want alerts again.
Watch answers whether the public origin changed. It is not a pentest and not a custom-depth scheduler.
Pick Standard or Deep when you add the site. Daily pulse is the same on every seat. Quick and Comprehensive are not Watch tiers; run those from the dashboard with credits, or use Scheduled Scans for a custom calendar.
Baseline runs do not spam existing findings. Alerts start when the site changes, the score drops, or a cert window is hit.
Run pulse now is limited to once per 15 minutes. Run weekly Standard now or Run weekly Deep now is limited to once per 6 hours. The included daily and weekly schedule still runs on its own.
How Watch looks for agencies, certificate expiry, and accepted staging risk.
Add five HTTPS origins on monthly Standard. Stripe quantity becomes five. Occupied seats show Watching 5 of 5. Included runs do not consume credits. A Deep origin is a separate $49 seat, not an extra Standard quantity.
A pulse records the tightest window, 14 days, then later 7 days, then expired. Quiet hours can delay the mail until morning in the watch timezone.
Staging is missing HSTS on purpose. Mute it. The row shows a Muted pill and Unmute. Production still alerts. When staging should be strict, click Unmute.
Pick the product that matches the question you need answered.
| Product | Cadence | Billing | Credits | Best for |
|---|---|---|---|---|
| Website Watch | Daily pulse + weekly Standard or Deep | Standard $29 / Deep $49 per site / month | Included runs use none | Know when the public origin changed |
| Scheduled Scans | Custom calendar and depth | Plan or credits | Yes | Repeat Comprehensive or a custom weekday |
| Penetration Test | One engagement plus retests | $297 or $497 | Separate product | Verified automated evidence-backed testing |
Silence one accepted finding without turning Watch off.
Go to /watch, click the site, and find the finding under Open issues.
Click Mute. The row shows a Muted pill and is listed under Muted issues. Later pulses still see the issue, but that fingerprint drops out of new-finding email.
Click Unmute on the same open-issue row, or in Muted issues. Alerts for that fingerprint resume on later change detection. You do not need support to clear a mute. Do not turn off New findings globally to hide one staging quirk.
Step-by-step setup, troubleshooting, and more examples live in Website Watch documentation and Website Watch help.
Billing, credits, mute, and how Watch differs from Scheduled Scans and pentest.
Watch is always-on monitoring for one HTTPS origin. Vulnify runs a daily pulse (headers, certificate expiry, exposed paths) and one weekly Standard or Deep scan, chosen when you add the site. You get an email when something new appears.
Add an HTTPS site, pay per seat, and get mail when the public surface changes.